Verification Bypass in jsonwebtoken
Critical severity
GitHub Reviewed
Published
Oct 9, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Oct 9, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions 4.2.1 and earlier of
jsonwebtoken
are affected by a verification bypass vulnerability. This is a result of weak validation of the JWT algorithm type, occuring when an attacker is allowed to arbitrarily specify the JWT algorithm.Recommendation
Update to version 4.2.2 or later.
References